NIS2 and the Cybersecurity Act for SMEs

Since 15 August 2026, the Cybersecurity Act, the Dutch elaboration of the European NIS2 Directive, has been in force. More than eight thousand organizations are directly covered by it. Chances are that your company is not among them.

And yet you have to deal with it. The companies that do fall under it must screen their suppliers. If you supply to a producer, a healthcare institution, an energy company or a large client, the questionnaire will soon be on your table.

Clarity

Do you fall under it, yes or no

Demonstrably

Recorded what you have arranged

Honest

Even if you don't have to do anything

NIS2 en de Cyberbeveiligingswet: valt jouw mkb-bedrijf eronder?

CYBER SECURITY ACT

Does your company fall under the Cyber Security Act?

Two things determine that: your sector and your size. The law applies to eighteen designated sectors, and you are big enough as soon as you have 50 or more employees, or less than 50 employees but an annual turnover and a balance sheet total above ten million euros. In practice, we see three situations:

  • You fall directly under it. Then legal obligations apply: registering, managing risks, reporting incidents and organising administrative involvement.
  • You don’t fall under it, but your customer does. It must have its chain in order and passes on the requirements in contracts and questionnaires. By far the most common in SMEs.
  • Neither, for now. Then you don’t have to do anything. That’s what we just say.
Leveranciersvragenlijst NIS2: wat je klanten je gaan vragen

SUPPLY CHAIN

What your customers will ask you

Even without a legal obligation, these questions come your way: how are you protected and can you prove it, how quickly will we hear if you are hacked, do you have backups and have they been tested, who has access to our data, and do you work with multifactor authentication? You already have an answer to most of them if your IT is in the right place. The problem is usually not the technique, but that no one has written it down.

Leveranciersvragenlijst NIS2: wat je klanten je gaan vragen
Nexer regelt de technische en organisatorische kant van NIS2

DEMARCATION

Honest about what we don't do

We are an IT partner, not a lawyer and not an auditor. We take care of the technical and organizational side: security, backups, access management, monitoring and documentation. For a formal certification or a legal test, we refer you to a party that is allowed to do so. For the technical audit, we work with a security assessment. We prefer to tell that in advance rather than afterwards.

THE OBLIGATIONS

What the law requires of you in concrete terms

Registration obligation

You register your organisation in the NCSC entity register.

Duty of care

A risk analysis, and on that basis appropriate and proportionate measures.

Duty to report

Significant incidents must be reported to your CSIRT and supervisor within the statutory periods.

Administrative responsibility

The board is ultimately responsible and must be able to assess the risks.

OUR APPROACH

How we help you

1

Baseline measurement

Are you covered by the law? If not, what are your customers realistically going to ask?

2

Gap analysis

What is already there and what is missing. Often eighty percent turns out to be there.

3

Priority plan

Not a list of forty points, but the order in which it makes sense.

4

Execute and capture

We arrange the measures and document them so that you can show them.

CUSTOMER CASES

Companies that have their basics in order

WHY NEXER That's

why you choose Nexer

Personal approach and customization

No ready-made packages, but IT that is tailored to how your company actually works and where it wants to grow.

Efficiency and cost savings

We tailor your IT environment to what your business really needs, so you don't pay for redundant features or licenses.

Innovation at your pace

Whether you want to switch quickly or prefer to innovate step by step: we ensure that your IT environment always matches this.

Proactive

We think ahead. With proactive monitoring and advice, we identify risks before they become a problem in the workplace.

FAQ

Frequently asked questions about NIS2

NIS2 is the European directive. It does not work directly; Each country must translate it into its own legislation. In the Netherlands, this law is called the Cybersecurity Act, and it has been in force since August 15, 2026. The Cybersecurity Act replaces the old Network and Information Systems Security Act. In practice, people mean the same thing by “NIS2” and “the Cybersecurity Act”.

Legally probably not: in most cases, the law only starts with 50 employees, or with fewer than 50 employees with an annual turnover and balance sheet total above ten million euros. Please note two things. Parent companies and subsidiaries are included in that calculation, and for some types of organizations there is no size requirement at all. But the most important reason to do something with it is your customer: he must have his chain in order and will make demands on you. That’s not a law, that’s your contract.

For organisations covered by the law: supervision and enforcement by the designated supervisor. There is no general transition period, so those who have yet to start start with a backlog. For the rest, the risk is mainly commercial: you lose assignments because you cannot complete a supplier questionnaire. That is not a fine, but it does cost turnover.

No. A certification helps and makes it easier to explain, but it is not mandatory and does not automatically cover everything the law requires. What matters is that your measures are appropriate to your risks and that you can demonstrate them. A well-substantiated file without a certificate is worth more than a certificate that no one cares about.

That depends on what is already there. In companies where the basis is good, it is mainly about recording and supplementing; then you are talking about weeks. For companies that are lagging behind, it is a process of months, because a few things have to be done technically. The baseline measurement provides clarity within a few days about which category you are in.

CONTACT

Not sure if NIS2 applies to you?

That’s exactly where most companies are now. Request the baseline measurement, then you will know within a week whether you need something and if so, what. Is there already a questionnaire from a client? Send it along, and we’ll look at it right away.

Do you want to have the technology behind it tested? Then take a look at our security audits.

Instant Help

First aid for support

Instant Help

First aid for support